Impact
Cap’s GET /api/video/ai endpoint does not verify the requester’s ownership or group membership before returning private AI‑generated metadata such as titles, summaries, and chapters. As a result, any authenticated user can supply an arbitrary video identifier, read confidential AI, and trigger additional AI‑generation operations that consume the video owner’s credits.
Affected Systems
The affected vendor is Cap:Cap. The product is the Cap platform’s Video AI service. No specific product or version numbers were supplied, so all current releases of Cap are potentially affected until a fix is applied.
Risk and Exploitability
The vulnerability scores a CVSS of high severity. The likely attack vector is an authenticated network fact that the endpoint requires valid credentials, making it a network‑based, authenticated score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation at present. Nevertheless, the combination of confidentiality loss and resource consumption creates a significant risk for impacted organizations.
OpenCVE Enrichment